π¨ Critical Security Alert! GitLab issues patches for CVE-2023-5009, a flaw allowing attackers to run pipelines as other users.
Protect your codeβupdate now: https://thehackernews.com/2023/09/gitlab-releases-urgent-security-patches.html
Protect your codeβupdate now: https://thehackernews.com/2023/09/gitlab-releases-urgent-security-patches.html
π21π₯6π2
π‘οΈ Signal messaging app's latest update adds a quantum-resistant shield. Learn how the PQXDH protocol boosts encryption against future quantum threats.
Details here: https://thehackernews.com/2023/09/signal-messenger-introduces-pqxdh.html
Details here: https://thehackernews.com/2023/09/signal-messenger-introduces-pqxdh.html
π19π€12π₯10β‘5
π¨ Alert: Chinese-language speakers under attack!
Multiple email phishing campaigns are distributing dangerous malware, including ValleyRAT.
Read: http://thehackernews.com/2023/09/sophisticated-phishing-campaign_20.html
Multiple email phishing campaigns are distributing dangerous malware, including ValleyRAT.
Read: http://thehackernews.com/2023/09/sophisticated-phishing-campaign_20.html
π16π₯11
Beware of npm imposters! 14 fraudulent packages found in the registry, posing as legit tools. They aim to steal your Kubernetes configs and SSH keys.
Read: https://thehackernews.com/2023/09/fresh-wave-of-malicious-npm-packages.html
Read: https://thehackernews.com/2023/09/fresh-wave-of-malicious-npm-packages.html
π13π€―6π₯2
Attention IT admins! Update Nagios XI to version 5.11.2 now. The network monitoring software has patched four critical security flaws (CVE-2023-40931 to CVE-2023-40934), protecting against privilege escalation and information disclosure.
Read: https://thehackernews.com/2023/09/critical-security-flaws-exposed-in.html
Read: https://thehackernews.com/2023/09/critical-security-flaws-exposed-in.html
π24π₯3π2
π¨ Beware of Fake Exploits! A malicious actor tried to trick users with a fake WinRAR PoC exploit on GitHub, aiming to infect them with VenomRAT malware.
Learn more: https://thehackernews.com/2023/09/beware-fake-exploit-for-winrar.html
Learn more: https://thehackernews.com/2023/09/beware-fake-exploit-for-winrar.html
π21π₯10π10π€―2
β οΈ Attention Linux users who downloaded the "Free Download Manager" software between 2020 and 2022:
Its website was breached in 2020, and a Ukrainian hacker group distributed malware.
Learn about the incident: https://thehackernews.com/2023/09/ukrainian-hacker-suspected-to-be-behind.html
Its website was breached in 2020, and a Ukrainian hacker group distributed malware.
Learn about the incident: https://thehackernews.com/2023/09/ukrainian-hacker-suspected-to-be-behind.html
π€―33π12π9π±7β‘6π₯1
Gold Melody, the financially motivated cybercrime group, is selling access to compromised organizations for ransomware attacks.
Researchers have revealed their tactics and targets: https://thehackernews.com/2023/09/cyber-group-gold-melody-selling.html
Researchers have revealed their tactics and targets: https://thehackernews.com/2023/09/cyber-group-gold-melody-selling.html
π11π9π₯1
π¨ China's Ministry of State Security accuses the U.S. of cyber espionage against Huawei servers since 2009.
Read: https://thehackernews.com/2023/09/china-accuses-us-of-decade-long-cyber.html
Read: https://thehackernews.com/2023/09/china-accuses-us-of-decade-long-cyber.html
π27π12π₯8π€7
π¨ P2PInfect Worm Alert : P2PInfect malware activity skyrockets 600x in a week. Researchers shed light on its rapid growth and evolving tactics.
Read: https://thehackernews.com/2023/09/researchers-raise-red-flag-on-p2pinfect.html
Read: https://thehackernews.com/2023/09/researchers-raise-red-flag-on-p2pinfect.html
π16π₯8π4β‘1
Sandman, a new cyber threat actor, is targeting telecom providers across continents. Read more about this cyber espionage campaign.
Read: https://thehackernews.com/2023/09/mysterious-sandman-threat-actor-targets.html
Read: https://thehackernews.com/2023/09/mysterious-sandman-threat-actor-targets.html
π15π₯11β‘2
π¨ Attention users! Apple issues patches for 3 new critical zero-day flaws impacting iOS, iPadOS, macOS, watchOS, and Safari. Stay safe with the latest updates for your devices.
Read details: https://thehackernews.com/2023/09/apple-rushes-to-patch-3-new-zero-day.html
Read details: https://thehackernews.com/2023/09/apple-rushes-to-patch-3-new-zero-day.html
π19π11π7π€7π₯2
π¨ Security Alert! Atlassian and ISC uncover critical flaws in their products that could lead to DoS and remote code execution attacks.
Read and patch now: https://thehackernews.com/2023/09/high-severity-flaws-uncovered-in.html
Read and patch now: https://thehackernews.com/2023/09/high-severity-flaws-uncovered-in.html
π21π3π₯1
OilRig, Iran's state-backed actor, aims at Israeli entities with spear-phishing tactics. Learn about the Outer Space and Juicy Mix campaigns.
Read: https://thehackernews.com/2023/09/iranian-nation-state-actor-oilrig.html
Read: https://thehackernews.com/2023/09/iranian-nation-state-actor-oilrig.html
π€14π12π4π2π±2π₯1
Ever wondered how MITRE Engenuity evaluates cybersecurity vendors?
Discover how to interpret MITRE ATT&CK Evaluation results and find the perfect security fit for your organization.
Read: https://thehackernews.com/2023/09/how-to-interpret-2023-mitre-att.html
Discover how to interpret MITRE ATT&CK Evaluation results and find the perfect security fit for your organization.
Read: https://thehackernews.com/2023/09/how-to-interpret-2023-mitre-att.html
π13π4π₯2
π°π Beware Latin America! BBTok banking trojan strikes Brazil & Mexico. Crafty phishing emails, unique payloads, and a sneaky approach put users at risk.
Learn how to shield your finances from this stealthy attacker: https://thehackernews.com/2023/09/new-variant-of-banking-trojan-bbtok.html
Learn how to shield your finances from this stealthy attacker: https://thehackernews.com/2023/09/new-variant-of-banking-trojan-bbtok.html
β‘15π7π₯5π5π€―5
π¨ ALERT: iPhone spyware attack!
Former Egyptian parliament member Ahmed Eltantawy targeted by Predator spyware using 3 recent zero-day vulnerabilities.
Learn more: https://thehackernews.com/2023/09/latest-apple-zero-days-used-to-hack.html
Former Egyptian parliament member Ahmed Eltantawy targeted by Predator spyware using 3 recent zero-day vulnerabilities.
Learn more: https://thehackernews.com/2023/09/latest-apple-zero-days-used-to-hack.html
π€―30π13π11π9π₯6
Researchers uncovered a new advanced backdoor, 'Deadglyph,' by Stealth Falcon hackers, which combines two languages for cyber espionage.
Read: https://thehackernews.com/2023/09/deadglyph-new-advanced-backdoor-with.html
Read: https://thehackernews.com/2023/09/deadglyph-new-advanced-backdoor-with.html
π₯20π10π€―6π€1π±1
Espionage Alert: Southeast Asian government targeted by China-nexus threat actors. A three-part report by Palo Alto Networks reveals distinct clusters and sophisticated tactics.
Read more β‘οΈ https://thehackernews.com/2023/09/new-report-uncovers-three-distinct.html
Read more β‘οΈ https://thehackernews.com/2023/09/new-report-uncovers-three-distinct.html
π±12π10π₯4π2π€1
EvilBamboo tactics exposed: Targets sensitive data from Tibetan, Uyghur, and Taiwanese organizations. Utilizes fake websites and social media for deploying exploits.
Read details: https://thehackernews.com/2023/09/from-watering-hole-to-spyware.html
Read details: https://thehackernews.com/2023/09/from-watering-hole-to-spyware.html
π15π€6β‘1π1